We have been quiet, but we have not forgotten you. We're back, and with us we bring our flagship Hunting Zero-Days in Embedded Devices course... but this time, it's online and on-demand!
More information below (& a massive launch discount code in the thread) 👇
My team EDG at NCC Group is looking for an experienced vuln researcher/exploit developer! RT's welcome!
This is a full time R&D role, primarily contributing to the developing of capabilities for consultants, showcasing knowledge, collab with other teams etc. We work across many disciplines in security research. Interested in AI applied to VR/exploit dev too.
We can recruit in UK/Spain (remote or hybrid).
https://t.co/kNTDcH4Imb
.@BobDaHacker compromised FIFA and was able to hijack their livestream cameras.
They considered replacing the FIFA cameras with the 1987 hit classic "Never Gonna Give You Up" by Rick Astley. Instead, they reported it and FIFA immediately fixed the issue
https://t.co/MVfGwOnNoa
After 6 months of extensive research, I have finally published a new blog post! It describes the journey from breaking into my router using a couple of command injections to finding and exploiting a remote heap overflow in a MediaTek kernel driver :D
https://t.co/FeOrZm0fPa
Hiring for several offensive security research roles 🔍
📱 Senior Offensive Security Researcher — Android Chromium Sandbox Security
🌐 Offensive Security Researcher — Browser
🍎 Offensive Security Researcher — iOS Kernel
Role links in the first reply. Please share if someone great comes to mind 🙌
#Hiring #CyberSecurity #OffensiveSecurity #Infosec
We've broaden the search to include iOS reverse engineers (besides exploit developers). Can't believe I need to say this but WE ARE NOT LOOKING FOR APP DEVS!
Fully remote work, great pay, handsome bonuses for the right person!
Looking for an experienced iOS exploit developer!
Minimum 4 years of experience, to work in a world-class exploit dev team. Must be familiar with userspace iOS exploitation. Fully remote, top tier salary, best bonuses in the field - ping me now
I've made hundreds of Python scripts that are named "aa", "aaaaaaa", "shdbcvsduv", "111222111", etc. I just kind of mash the keyboard until there isn't a file name collision
Now I sit here, alone in my room, questioning the meaning of life as I once again try to find the script I need in an ocean of "aa", "aaa", "aaaaaa", "abcdv", "112456", etc.
There are countless tutorials, blog posts, and workshops on how to exploit a vulnerability. What’s missing is the thought process — how you approach a target, form hypotheses, and ultimately discover a bug. That mindset can’t be fully taught; you have to develop it yourself ;)
Looking for exploit kings with experience with Scudo / Jemalloc:
- 100% remote working environment
- Leet colleagues from 3 continents
- Fantastic salary and bonuses
- 2x yearly team meets worldwide!
- MUST HAVE European, North American or Australian / NZ citizenship!
PM 📩
Guys I have been flooded in my DM by web3 and web2 security researchers - sorry for not being specific in the original post - I'm looking for BINARY / EXPLOITATION reverse engineers.
We are looking for a junior security researcher 🤠
No university degree or previous work experience required, but MUST be able to demonstrate interest in the field and some basic skills by either:
1. Have published blog post detailing 0-day vulnerability (found by yourself) or n-day (analysing someone else's vuln in detail), preferably with exploit code published for the vuln detailed in the blog post.
2. We can also accept private write-ups for vulns you have found / exploited but never published (even if they are already fixed).
3. OR if you don't have any of the above, but have a way to prove your skill, hit me up and we'll talk!
We're also accepting mid-level security researchers with a few years experience!
What we offer:
- Fully remote working environment with regular company meet-ups.
- Great salaries and bonuses!
- Flexibility to work on different CUTTING EDGE projects (mostly related to mobile).
- Mentoring and training by some of the world's top security researchers
Hahahahhahahaha
Unironically a good idea. It's so unbelievably stupid and it works. Depending on explorer layout, the .exe might not be visible.
Filename.mp4 + ??? spaces + .exe
Hahahahahaha UNC6032 is wild as hell
Pwning basebands is often seen as black magic, but it’s surprisingly easy to start... if you know how 😁
Practical Baseband Exploitation teaches you to reverse engineer basebands, find vulnerabilities, and program BTS to exploit them over-the-air.
This year, the course is at @reconmtl in June and @hexacon_fr in October. These may be the last public sessions, as we’re going fully private next year!
https://t.co/MSj1nVQsi3
https://t.co/9EYdcBTtEO